PT-2024-34340 · Softwarex · Softwarex

Daniel Hirschberger

+1

·

Published

2024-12-12

·

Updated

2024-12-13

·

CVE-2024-50584

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SoftwareX versions (affected versions not specified)
Description: An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the "/class/template io.php" file and supplying malicious GET parameters. The templates parameter is vulnerable to blind boolean-based SQL injection attacks. SQL syntax must be injected into the JSON syntax of the templates parameter.
Recommendations: As a temporary workaround, consider restricting access to the "/class/template io.php" file until a patch is available. Avoid using the templates parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-50584

Affected Products

Softwarex